Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4092

Published Nov 29, 2009

Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4091

Published Nov 29, 2009

comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via the (1) edit or (2) del acti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4090

Published Nov 29, 2009

Unrestricted file upload vulnerability in ajax/addComment.php in telepark.wiki 2.4.23 and earlier script allows remote attackers to execute arbitrary code by uploading a file with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4089

Published Nov 29, 2009

telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4088

Published Nov 29, 2009

Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parame…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4087

Published Nov 29, 2009

Cross-site scripting (XSS) vulnerability in index.php in telepark.wiki 2.4.23 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4086

Published Nov 29, 2009

CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4085

Published Nov 29, 2009

PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[B…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4084

Published Nov 29, 2009

SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4083

Published Nov 29, 2009

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) submitn…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4082

Published Nov 29, 2009

PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to execute arbitrary PHP code vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4032

Published Nov 29, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4031

Published Nov 29, 2009

The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4018

Published Nov 29, 2009

The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4079

Published Nov 25, 2009

Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via un…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4078

Published Nov 25, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4077

Published Nov 25, 2009

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4076

Published Nov 25, 2009

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4075

Published Nov 25, 2009

Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4074

Published Nov 25, 2009

The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4022

Published Nov 25, 2009

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabl…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4021

Published Nov 25, 2009

The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer deref…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4073

Published Nov 24, 2009

The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4072

Published Nov 24, 2009

Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 476-500 of 5,732 CVEsPage 20 of 230